#VU123489 Missing Authentication for Critical Function in ActiveMQ Artemis and Artemis - CVE-2026-27446
Published: March 4, 2026
ActiveMQ Artemis
Artemis
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to missing authentication checks within the Core protocol. A remote non-authenticated attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker and inject messages into any queue and/or exfiltrate messages from any queue via the rogue broker.